Port Scan Detected
Medium
Open
ALR-00006 · 2026-05-22T13:52:47Z
Description
Sequential port scan (1-1024) detected targeting FW-EDGE-01 from external IP. DecoyPulse identified SYN scan pattern.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
13:52:47
Event ingested by SOC365 Engine
13:52:52
EmilyAI triage started — correlation enrichment
13:53:01
EmilyAI confidence: 84% — escalated to human analyst
13:53:11
Alert assigned to analyst: Emma Richardson
13:55:01
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00063 | 1h ago | Port Scan Detected | Medium | Open | WS-LAP-010 |
| ALR-00271 | 1h ago | Port Scan Detected | Low | Open | VM-DEV-01 |
| ALR-00171 | 3h ago | Port Scan Detected | Low | False Positive | WS-MAC-005 |
| ALR-00024 | 6h ago | Kerberoasting Attempt | Informational | Resolved | FW-EDGE-01 |
| ALR-00418 | 9h ago | DecoyPulse Honeypot Triggered | Low | Escalated | FW-EDGE-01 |